A Penetration Tester, also known as an ethical hacker, is a cybersecurity professional who simulates cyber attacks on computer systems, networks, and applications to identify and fix security vulnerabilities. Their work is essential in protecting sensitive data and preventing unauthorized access from real hackers.
Education: Bachelor's degree
Years in related career: None
On-the-job training: None
Projected Growth: 9.7% (far above average)
Annual job openings: 31,300
Direct AI exposure: 32% of tasks
Potential AI exposure: 86% of tasks
| According to the U.S. Bureau of Labor Statistics, average income (in USD) in 2025 was $117K per year. | ||||
|---|---|---|---|---|
| Bottom 10% | Bottom 25% | Median (average) | Top 25% | Top 10% |
| $56K per year | $79K per year | $117K per year | $158K per year | $188K per year |
| Compared to other careers: Median is $66K above the national average. | ||||
Penetration Testers typically work in office settings within cybersecurity firms, IT departments of various companies, or as independent consultants. The role often involves collaborating with IT teams and may include remote work. They may work regular hours, but projects can sometimes require work outside of typical business hours.
Penetration Testers are on the front lines of cybersecurity, using their skills to strengthen the digital defenses of organizations. They think like hackers to uncover weak points in security before actual malicious attackers can exploit them. Their role involves a mix of hands-on technical work and strategic planning, as they must understand and anticipate the tactics that real-world hackers might use.
In addition to technical expertise, Penetration Testers need to be creative and analytical problem solvers. They often use a variety of tools and techniques to probe for vulnerabilities, requiring a deep understanding of both the technology they are testing and the potential methods of attack. This career is dynamic and fast-paced, as cybersecurity threats continually evolve, requiring Penetration Testers to be lifelong learners.
Strong communication skills are also important, as Penetration Testers need to explain their findings and recommendations to non-technical stakeholders. They must be able to document their methods and findings clearly and provide actionable insights to improve security.
A bachelor's degree in cybersecurity, information technology, computer science, or a related field is commonly required, amounting to about 4 years of post-secondary education. Additional certifications in cybersecurity or ethical hacking are highly valued.
Similarity is based on what people in the careers do, what they know, and what they are called. The process of establishing similarity lists is described in this white paper.